Free Phishing Test
REGULACJE PRAWNE

How to Properly Perform KSC Self-Identification? Free Tools and Practical Examples

15-jul-2026 17 minutes read

KSC self-identification is an independent assessment of whether the organization is subject to the Act on the National Cybersecurity System (KSC), implementing the NIS2 directive, and assigning itself to one of three categories: key entity, important entity or no obligation. To conduct it, you need to check the sector of activity, the size of the enterprise and the conditions set out in Art. 5 of the Act. The result of positive qualification is the obligation to enter the KSC Register by October 3, 2026. The amendment to the KSC Act will cover, according to the estimates of the Ministry of Digitization, approximately 38-42 thousand entities subject to regulation in Poland.

What is self-identification in KSC?

You may be running a company operating in a sector covered by the regulations KSC 2.0. However, you have not received an official letter informing you that from today you are a key or important entity. Your organization must be the first to check whether the new obligations actually apply to it.

This is what self-identification is all about. This is an independent assessment of whether the activities conducted are subject to the KSC 2.0 Act, and if so, whether the organization should be classified as a key entity or an important entity. The starting point for such an analysis is Art. 5 of the Act and Annexes No. 1 and No. 2, which indicate the sectors, subsectors and types of activities covered by the regulation.

In practice, however, it is not enough to check the PKD code entered in the National Court Register. What is much more important is what the company actually does, what services it provides and on what market it operates. If the organization’s actual activities fall within the sector covered by the Act, the provisions may apply even if the main PKD code does not indicate so.

Properly performed self-identification should result in a clear answer:

  • the organization is a key entity,
  • is a valid entity
  • or is not subject to the provisions of the Act.

If the analysis shows that the company belongs to one of the first two categories, the next step will be to make an entry in the KSC List. This is an official register of key and important entities, kept by the Minister of Digitization in the application wykaz-ksc.gov.pl and technically based on the S46 System.

Who is obliged to self-identify?

The obligation to self-identify applies to every entity operating in the sector indicated in the annexes to the Act on the National Cybersecurity System – regardless of whether it is a private company, a company with local government participation, or an office. Two pillars determine membership in the system: sector of activity and size of the organization.

The sector decides whether a given activity is included in the catalog protected by the Act at all – energy, finance, health care, transport, water and sewage management and several other industries listed in Annexes 1 and 2 (read more in the article about the amendment to the KSC). However, size determines which of the two categories of entities an entity that meets the sector criterion falls into.

The key entity criteria from Annex 1 differ from the important entity criteria from Annex 2 primarily in the importance of the potential effects of the incident on the state and the economy, not in the assessment mechanism itself.

  • Key entities are organizations whose disruption would have the most serious consequences for the state and economy.
  • The important entity includes other industries added by the amendment, where the incident is serious but less severe on a national scale.

When calculating the size, not only one’s own employment and finances are taken into account, but also related and partner enterprises – a Polish company may suddenly become a large entrepreneur through a foreign investor or shares in a capital group, even if it employs few people itself. The Act on the National Cybersecurity System does not distinguish between the private and public sectors: the obligations cover both, and the fact that the owner of the company is a commune or the State Treasury does not in itself determine the qualification.

We can help you determine whether your organization is subject to KSC – as part of an ISMS audit, which combines the perspective of a legal advisor with technical security diagnosis and practical team training.

How to self-identify KSC? Three steps according to the Ministry of Digitization

The Ministry of Digitization divides the self-identification process into three steps: checking the sector, determining the size of the enterprise and analyzing Art. 5 of the Act. The order matters – only the result of all three steps together gives the answer whether the entity is key, important, or not subject to the Act at all.

01 Check your business sector

The first step is to verify whether the business activity is within the sectors or subsectors indicated in Annex No. 1 (key entities) or Annex No. 2 (important entities) to the Act. The Ministry of Digitization emphasizes that what matters in this assessment is the actual nature of the business, and the PKD code has only auxiliary meaning – the actual scope of services provided or tasks performed is decisive, not the entry in the register.

For example, a company that operates in one industry on paper, but actually provides services from the sector covered by the Act – e.g. as a subcontractor in the energy or health care supply chain – should verify itself in relation to this real scope of activity, not in relation to the code in the National Court Register. Even an entity providing services only partially covered by the Act should analyze this part of its activities separately.

02 Specify the size of the company

The second step is to determine the size of the entity according to the thresholds of micro, small, medium and large enterprises, including affiliated and partner enterprises.

The thresholds are checked separately: it is enough to exceed one criterion – employment or financial – for the company to be placed in a higher size category, even if the second criterion remains unmet.

There is one clear exception to this rule. Telecommunications undertakings covered by the amendment to the Act, regardless of their size, have a different qualification threshold for the key/important category than other industries:

SizeType of entity (telecommunications undertaking)
Large entrepreneurkey entity
Medium-sized entrepreneurentity key
Small entrepreneurimportant entity
Micro-entrepreneurimportant entity

This is exactly the exception explained by the case from our webinar about KSC: a telecommunications organization employing less than 50 people, but with a revenue of over EUR 10 million, is a key entity – despite the small number of employees, because in telecommunications already an average entrepreneur has the status crucial, not important.

We invited a legal advisor and a partner of a digital law firm to a discussion about UKSC / NIS2, during which we broadly discussed the topic of self-identification and entry into the KSC List – receive free access to the recording and additional materials!

03 Analyze the article. 5 of the Act

The third step is the analysis of art. 5 of the KSC (Article 5 of the Act on the National Cybersecurity System), which specifies detailed rules for recognizing entities as key or important, including cases of being covered by the Act, regardless of their size. Only after analyzing this provision can you finally determine whether the entity is key, important or not subject to the provisions at all

Meeting the conditions of Art. 5 clearly means that the entity will be subject to the provisions of the Act regardless of the result of the second step – it is this path that allows, for example, a small municipal company to fall into the category of an important entity despite not meeting the size thresholds (full case in the section below). In some cases, an organization that does not formally meet the size criteria, but meets the sectoral conditions set out in Art. 5.

Additional tools to help with self-identification

Before you start manual analysis from scratch, compare your findings with ready-made tools:

  1. SME qualifier from PARP – the official tool for determining the size of an enterprise.
  2. UKSC/NIS2 Validator by Muszyński Law Firm – a free preview tool covering all three steps.
  3. Guides of the Ministry of Digitization – official explanations and answers to questions, updated on an ongoing basis.

None of these tools is a substitute for legal analysis. They provide an indicative result, based on data that you enter yourself – they do not take into account nuances such as affiliated enterprises, sector exceptions or the conditions under Art. 5.

If you have any doubts about the qualifications of key and important entities, it is best not to guess on your own – contact us to discuss the result of self-identification and the scope of the ISMS audit tailored to your organization.

Key or important entity? Examples of qualifications from practice

The sector and size criteria themselves sound simple on paper, but in practice, lawyers specializing in KSC regularly receive questions about borderline cases. The table below shows six typical situations and their qualification score.

Municipal company: waterworks and sewage, 20 employees

Limited limited liability company with 100% of the commune’s shares, operating in the water and sewage sector (Annex No. 1) and employing 20 people, does not reach the threshold of an average entrepreneur in terms of size. Nevertheless, it qualifies as an important entity – it does not meet the size criteria, but carries out a public utility task using information systems (Article 5(2)(8) of the UKSC).

Telecommunications entrepreneur below the employment threshold

A telecommunications company employing less than 50 people but with revenues exceeding EUR 10 million meets the criteria of a medium-sized entrepreneur despite low employment. In telecommunications, a medium-sized entrepreneur already has key status – this is a sector exception, so the company qualifies as a key entity.

Energy operator with over 250 employees

A large energy company (Annex No. 1), employing over 250 people, qualifies as a key entity – the sector and size clearly indicate this. However, it is worth remembering that some operators of particular importance for the energy system (e.g. transmission system operators) may be key entities regardless of their size – similarly to the telecommunications exception described above. Therefore, step 3, i.e. analysis of Art. 5, it is worth verifying even in seemingly obvious cases.

Catering company outside the sectors from the attachments

A small catering company employing 15 people operates outside the sectors indicated in the annexes to the Act – it is not subject to the KSC. The food sector covered by the amendment mainly concerns wholesale distribution and large-scale industrial production and processing of food, not catering and catering services operating locally. A company from the food industry should check on which side of this border it actually is, instead of relying solely on the general term “food sector”.

IT supplier for the energy operator

A small IT company (30 employees), providing services to an energy operator, does not itself operate in the sector indicated in the attachments – it is not automatically covered. Being a supplier of an entity covered by the KSC does not in itself determine coverage by the Act, but the contractor may impose contractual requirements.

The result of self-identification based on sector and size is not always final

The Act provides for an additional path: the minister may, by administrative decision, recognize an entity as key if it is the only one providing a service of key importance for critical social or economic activity via an information system – regardless of the fact that according to the size thresholds the entity would be considered important or even outside the scope of the Act. This applies, for example, to the only water supplier in the commune, with no alternative for residents: lack of competition on the local market may be the basis for the minister’s decision, even if the company does not meet the threshold of a medium-sized entrepreneur.

A separate category consists of digital service providers (e.g. providers of cloud, trading platforms or internet search engines) andexisting key service operators, operating under the old Act of 2018 – both groups were entered into the KSC List ex officio, without the need for self-registration.

The case of a municipal company from the table above comes directly from the questions asked at our webinar on the implementation of KSC. Legal advisor Jerzy Muszyński explained when such a company may be considered an important entity despite not meeting the employment threshold:

It may be determined by the fact that the company carries out public tasks, a public utility task within the meaning of the Municipal Economy Act, and carries out public tasks using information systems.
Jerzy Muszyński, legal advisor at SECAWA

Marcin Serafin drew attention to a threshold that is easy to forget about in such a company – the number of employees is not the only criterion:

This is something that could potentially be important […] because if it is to reach this threshold of ten million euros in turnover or balance sheet total, it will be subject to this regardless of whether it has twenty or two hundred employees.
Marcin Serafin, digital law specialist, partner of the Sterberg law firm

Twenty employees of a water and sewage company from our table are not enough to cross the threshold of a medium-sized entrepreneur – but if its turnover or balance sheet total reached EUR 10 million, qualification would be certain regardless of employment.

By when do you have to self-identify? Key terms

The deadline for self-identification and entry into the KSC List is October 3, 2026. The schedule is as follows:

  • until May 6, 2026 – ex officio entries: The Minister of Digitization registered existing operators of key services, digital service providers and trust service providers, telecommunications entrepreneurs and public entities.
  • May 7 – October 3, 2026 – window for self-registration for other entities that self-identification has classified as key or important.
  • April 3, 2027 – deadline for full implementation of the ISMS and connection to the S46 System, i.e. the central channel for the exchange of information and threat warnings between entities covered by the KSC and supervisory authorities.
  • April 3, 2028 – the first mandatory security audit and the beginning of fines.

Self-registration takes place via the Wykaz KSC application, after logging in with a trusted profile, e-ID, electronic banking or qualified signature.

The lack of penalties until 2028 does not mean the absence of an obligation – failure to self-identify and register is a violation of the regulations from day one, but not financially enforceable. Why this distinction can be confusing, we described in more detail in the article about why the lack of penalties until 2028 is a trap.

The most common errors when self-identifying and starting the implementation of the KSC Amendment

Legal advisor Jerzy Muszyński, based on implementation experience and control practice, pointed out six errors during the webinar that most often mean that the KSC implementation starts in the wrong direction from the very beginning:

  • Incorrect qualification – the company starts the implementation without thoroughly checking the sector, size and exceptions, or out of overzealousness it forces it into the list or confuses the important/key category. The result: an unnecessary project or overlooked responsibilities.
  • Omitting the supply chain – the organization only analyzes its own systems, without checking suppliers, clouds, software houses, services and subcontractors covered by ICT contracts.
  • “Colonel” – a set of documents purchased from an external company and hidden in a closet, without real processes, tests and proof of operation.
  • No owner – the topic goes to the IT department without a management decision, budget or clearly assigned business responsibility.
  • Unpracticed incident procedure – procedures exist on paper, but no one has tested them, so in a real situation it is not known who decides, who reports the incident and who contacts CSIRT.
  • Self-registration as a finish line instead of a start – entry in the KSC List treated as the end of the process, although it is only the beginning of the obligations: ISMS, risk management, incident handling, supplier supervision and audits.

The group of key and important entities that make these mistakes include both large, experienced organizations and those entering the system for the first time. KSC imposes the obligation not only to register, but above all to conduct real risk management – neglect of the duties of key entities is usually revealed only during an inspection or security incident.

Why is it worth leaving an evidentiary trail?

Self-identification without documentation is self-identification that does not exist in the eyes of the controller. As Jerzy Muszyński emphasized:

Every company should perform such self-identification and approach this self-identification in an evidential way, i.e. leave some trace of this self-identification.
Jerzy Muszyński, legal advisor at SECAWA

In practice, an evidentiary trail means a specific set of documents, not the decision itself recorded in an email or agreed at a management meeting. It’s worth preparing:

  • record of customers and services – what services the company actually provides and to whom, in order to be able to refer them to the sectors from Annexes 1 and 2
  • risk register – what threats are associated with this activity and its information systems
  • financial statement in relation to statutory thresholds – balance sheet total, annual turnover and number of employees, compared directly with the micro/small/medium/large thresholds
  • list of people included in employment – including people on civil law and B2B contracts, if they remain under the management or supervision of the company and provide services on a permanent basis
  • date and person responsible for the analysis – who, when and on what basis made the decision on the entity’s status

Such a set of documents serves two functions at once. Firstly, it organizes the analysis itself – it is difficult to confuse a category when the data is compiled in one place and not scattered in the memory of several people. Secondly, it becomes defensible material: if the regulator asks why the company qualified in a certain way, the answer is a document, not a memory from a conversation from a year and a half ago.

Self-identification documentation is not an isolated trace – it becomes the first element of broader information security management system (ISMS) documentation, which will need to be expanded after being included in the list. A positive result of self-identification triggers the obligation to enter the KSC List, and the documentation referred to above is proof that this entry obligation was preceded by a reliable analysis, not guesswork.

Application to the KSC List – frequently asked questions

What is self-identification in KSC? Self-identification is an independent assessment of whether an organization is subject to the Act on the National Cybersecurity System and assigning itself to the category of a key or important entity or determining that the Act does not apply to it. The analysis is carried out independently, without a request from the office.

By when do you have to self-identify? The window for self-registration in the KSC List lasts from May 7 to October 3, 2026. Entities entered ex officio – m.in. public and telecommunications entrepreneurs – were registered earlier, by May 6, 2026.

Is there a penalty for failure to report by October 3, 2026? Not immediately. Fines are in force only from April 3, 2028, but the registration obligation itself runs regardless of this exclusion – the delay does not eliminate the violation of the regulations, but only postpones its financial enforcement.

Is a company that is a supplier of an entity covered by the KSC also subject to the Act? Not automatically. The mere fact of being a supplier of a key or important entity does not determine coverage by the act, but the contractor may impose security requirements in the contract – this is a typical mechanism for spreading the obligations of regulated entities to the rest of the supply chain.

Does outsourcing at KSC exempt you from statutory obligations? No. Outsourcing at KSC – for example, outsourcing hosting, cloud or data center services to an external supplier – does not transfer statutory liability. The key entity ensures the security of its systems regardless of whether it maintains the infrastructure itself or through a subcontractor, and must supervise this as part of supply chain management.

What tools help in self-identification? The SME qualifier from PARP and the UKSC/NIS2 validator from the Muszyński law firm provide an indicative result based on self-entered data. None of them replaces legal analysis – if in doubt, it is worth consulting the result with a lawyer specializing in KSC.

Summary

Self-identification is determined at the intersection of three elements: the sector of activity, the size of the enterprise and the conditions set out in Art. 5 of the Act – none of them alone gives a certain answer. An error made at this stage costs more than the classification error itself: it leads to an unnecessary implementation project, overlooked responsibilities, or documentation that will not withstand the question of why the company qualified this way and not another.

The deadline for registration in the KSC List is October 3, 2026, and organizations that are already unsure about their status today usually do not start any other implementation work.

We implement KSC in the alliance of law (Kancelaria Muszyński) and technology (SECAWA) – from the qualification of the entity, through cybersecurity audit, to the action plan and team training. If you want to determine where your organization stands, ask about an ISMS audit.

Arrange an ISMS audit: legal analysis of the entity’s qualifications, technical security review and a report with action priorities in one study.

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579